[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: R41 in draft-ietf-v6ops-cpe-simple-security-07



On 28 jul 2009, at 19:22, Mohacsi Janos wrote:

Would it help to require a < 1024 port? On Unix-derived system you have to be root to be able to send those, so random applications wouldn't be able to do this without some serious tricking of the user.

I don't think so. Most of the Windows users using their systems as an Administrator. Administrator can do anything....

Does that mean an application can bind to a low port without the system throwing up some kind of yes/no choice? (Not that that's perfect, but it's something.)

Anyway the bots are preferring some exotic port numbers or portnumber that is usually not firewalled: 80 and 443.

If a bot wants to receive incoming traffic on those ports it would have to signal the CPE that it wants to be de-firewalled for those ports.

(Not that malware spreads by listening on those ports, listening on ports is _so_ 2003.)